Security2 distinct publishers2 min readPublished
The G7 Cyber Security Working Group's June call to action says the quantum threat is off the radar and under-resourced at most organizations, and it hands CISOs the wording to fund a cryptographic inventory this cycle.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The priority with teeth sits last on the working group's list of five: integrating PQC into cybersecurity requirements and procurement processes [9]. That turns a research topic into contract language, and contract language is what gets a control funded, through a vendor question, a renewal date or an audit finding. The group's diagnosis is financial rather than mathematical. It writes that the quantum threat "remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence" [4].
The federal migration date moved up by five years, from 2035 to 2030 [16]. Google's own target of 2029 sits inside that new deadline by one year, and inside the old one by six [17]. These are supply chain deadlines, not attacker deadlines: they land as security questionnaires and procurement clauses before the year printed on them, which is the practical reason an inventory started now costs less than one started in answer to a customer's renewal.
The report also pulls authentication into scope, warning that quantum computers could compromise authentication and assurance mechanisms by forging trusted data or stealing confirmation, putting secure communications and legal contracts at risk [8]. That is a different asset class from a transport session key. Code signing, document signing and long-lived trust roots have to stay verifiable years after the key was generated, so they belong near the top of an inventory rather than in the phase-two column.
Uncertainty in the algorithms themselves argues for inventory over algorithm shopping. Some of the NIST-selected algorithms have already been broken with traditional computers or AI, which is why the agency backs multiple algorithms and the concept of crypto-agility [13]. The deliverable that survives that churn is a map: where keys live, which algorithms and protocols consume them, when certificates expire. Inventorying and prioritizing critical systems is what governments have been recommending for years [20], and it holds its value even if a chosen algorithm fails and a second migration follows.
Progress so far splits along regulation. The transition is on schedule in the federal government and the highly regulated financial sector, and lagging in industries where owners and operators feel they have more immediate concerns [12]. Both groups face the same arithmetic, but only one of them has a regulator asking for evidence. The working group's answer is that this "can only be achieved with early engagement, coordinated planning and informed decision making across the public and private sectors" [19]. In budget terms, that means the inventory work falls to you and the schedule falls to your suppliers.
Ranked by verification strength, evidence, and original report placement.
CISA and the G7 Cyber Security Working Group released "Preparing for the Post-Quantum Era: A Call to Action," highlighting the need for organizations and governments to begin transitioning to post-quantum cryptography to protect sensitive data, authentication systems and critical assets.
The working group's report was prepared in June at the G7 Summit in France.
The report said organizations "can no longer afford to postpone" work transitioning critical systems and data to post-quantum forms of encryption.
The report said: "The quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence."
The report said a successful and collective transition to PQC "can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk."
The report said leaders in government and industry must reframe the quantum threat from a distant future problem to a near-term threat demanding action across all sectors, not just critical infrastructure.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Harvest now, decrypt soon: post-quantum migration is a funded program, not a research topic1 distinct publisher
security
Three-quarters claim a crypto inventory. Nearly half have nobody to hand it to.1 distinct publisher
build
JDK 24 relocates the post-quantum blocker to your key custody plumbing1 distinct publisher
leadership
Dropping Item 407(j) left boards learning cyber risk from the people they supervise1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One document, one reading of it
Every quotable line in this story traces to a single June document, and the only place we can read those lines is CyberScoop's article; CISA's own posting carries the five priorities and stops. Seven named agencies putting their names to the text is real weight, which is why this isn't thinner. But no one has checked the report's central assertion — that migration is under-resourced — against anything countable.
Dates committed, migrations uncounted
Three concrete adoption facts sit in this story and all three are calendar entries: 2030 for U.S. federal systems, 2029 at Google, and "on schedule" for federal and regulated finance. Not one figure describes systems actually re-keyed or inventories actually completed. The nearest thing to a measurement is the report conceding the work is not properly resourced at many organizations, and that points down.
New urgency, familiar advice
The rhetoric escalates — near-term threat, all sectors, economic risk — while CyberScoop notes the conclusions are largely what governments have recommended for years. Harvest-now-decrypt-later keeps the warning honest, and so does the reminder that these algorithms are designed against a machine that does not exist yet, using estimation that can be wrong. So: modestly overstated as an event, roughly right as a risk, and conspicuously short of anything binding or funded.
Written by the agencies who would administer it
The fifth priority is embedding post-quantum requirements into cybersecurity rules and procurement — drafted by the seven agencies that would write those rules. The executive order CyberScoop describes goes further, coupling the earlier deadline to boosting the domestic quantum industry, so security and industrial policy travel in the same document. Google's 2029 pledge is self-reported and unaudited. None of that makes the risk imaginary; it does mean nobody quoted in this story bears a cost if the deadline slips.
Firm on what was said, blind on what was done
What the report says is nailed down: long verbatim quotations, a named signatory list, a stated venue and month. What organizations are actually doing rests on one reporter's single sentence about who is ahead and who is behind, and on an unspecific aside about broken algorithms. Confident about the document; cautious about everything downstream of it.